# Trust is becoming an API

> Source: <https://chinaonchina.com/article/trust-is-becoming-an-api>
> Published: 2026-09-03 09:44:00+00:00

In the era of intelligent entities, companies are no longer competing for traffic, but for the qualification of "being trusted after machine verification"

Today's answer is quite embarrassing - it mostly relies on clues in the training data, piecing together search results, and probabilistically generating text that "looks most like the real thing". This is not a recommendation, it's a gamble. And when AI moves from chat windows to intelligent agents that automate procurement, lending, and contract signing, this gamble becomes real money and legal liability.

## From 'Recommendation' to 'Adjudication': A Fundamental Shift in AI's Role

In November 2024, Anthropic open-sourced the Model Context Protocol (MCP); by March 2026, its installation count had exceeded 97 million, with over 12,000 MCP servers online, and it was donated to the Agentic AI Foundation under the Linux Foundation for governance. According to Gartner, the popularization of MCP and its companion protocol A2A (Agent-to-Agent protocol) marks the AI agent's transition out of the "isolated tool" era and into its own "TCP/IP moment".

The significance of this protocol stack goes far beyond "enabling AI to call APIs". It connects AI, which was previously just a conversational model, to the real world, giving it hands and eyes: it can access ERP systems, read contracts, process payments, and place orders on your behalf. In 2026, official MCP servers from giants such as Salesforce, ServiceNow, SAP, Microsoft, and Google were launched, and 78% of enterprise AI teams have already begun using MCP in production environments.

However, the stronger the capability, the more glaring a long-neglected issue becomes: when an intelligent entity makes decisions on your behalf, what criteria does it use to judge whether the "other party is trustworthy"? While MCP is handing the world over to AI, no one has provided AI with a set of "trusted data sources".

## Illusion is Not a Bug, But a Structural Flaw: The Cost of Lost Trust

The cost is already being felt in real terms. Public cases include: a 237-page government review report by Deloitte Australia that fabricated non-existent academic papers and false case citations; a flagship report by KPMG that fabricated 40 out of 45 citations; a cybersecurity report by Ernst & Young that was found to have around 60% of its citations fabricated; and in April 2026, top law firm Sullivan & Cromwell apologized to a federal bankruptcy judge for misquoting the US Bankruptcy Code in an emergency motion. A more insidious harm is "secondary illusion pollution": an AI-generated citation is taken in as a real source by another AI's training data, solidifying the error into "authoritative" material, making it increasingly difficult for human researchers to distinguish between fact and fiction.

## Solution One: Trusted Data Space - Letting Trust Flow in a Controlled Environment

The first layer of trust issues is the credible and controllable circulation of the data itself, which is the direction being laid out at the national level.

For intelligent entities, the value of a trusted data space lies in its provision of a controlled circulation base for core trust elements such as corporate qualifications, performance, credit, and compliance. When a company's real operating data can be provided to decision-making systems for inquiry in an authorized and traceable manner under the premise of privacy protection, AI's "trust judgment" has a primary source of facts, rather than relying on memory and speculation.

Fourth, Solution Two: Third-Party Trusted Data MCP - Making "Trust" a Machine-Queryable Resource

With a data foundation in place, an "interface" is still needed, which is the second major value that MCP can provide, and also the most underestimated opportunity at present: third-party trusted data MCP.

The idea is straightforward - since MCP can enable intelligent entities to read databases and call APIs on demand, it is also possible to have a class of MCP servers that specialize in exposing "trust data": credit scores from third-party rating agencies, qualification and penalty records from regulatory authorities, industry-recognized certificates of performance, and verifiable digital identities (based on DID/C2PA certificates). Before making decisions on your behalf, intelligent entities can call these independent third-party MCP services in real-time to obtain verifiable, signed, and auditable trust evidence.

The key lies in the three words "third party". Trust loses its meaning once it is provided by the evaluated object itself; it must come from an independent source that has no interest in the transaction and the credentials can be verified by machines. This is also why "machine-readable trust credentials + independent third-party ratings" will become the factual input for intelligent decision-making.

## Solution Three: Trusted Data Infrastructure Requires Its Own 'Clearing Network'

A single data point and a single MCP channel are still insufficient to support a smart society. By analogy, it can be seen that information has HTTP, funds have payment and settlement networks, while trust data requires its own basic infrastructure layer - a cross-domain, cross-industry, and mutually recognizable trust certificate network.

Its design principles should be clear: first, verifiable, trust statements must be based on cryptographic credentials rather than natural language declarations; second, auditable, every "trust call" should leave a trace, and errors can be traced back; third, decentralized governance, to avoid a single platform becoming the only trust entrance and holding the entire ecosystem hostage. This is consistent with the design philosophy of the trusted data space, "consensus rules, multi-party subjects, and mutual recognition and interconnection", and is also in line with the route of MCP being governed by a neutral foundation.

## Beware the New Trust Intermediaries' Monopoly

A dose of cold water is needed here. Once the window for trust infrastructure is opened, the most dangerous outcome is not that "it can't be built," but rather that "it is built by a few people."

Therefore, the key to winning the battle of trust in data infrastructure lies not in how flashy the technology is, but in whether it is co-built by multiple parties, whether it has standardized interoperability, and whether it has neutral governance. A closed, exclusive, and non-migratable "trust" will ultimately devolve into a new form of hegemony; only an open, mutually recognized, and portable trust network is worthy of being called "infrastructure".

## Three Reminders for Decision-Makers

Content optimization is a necessary condition, but not a sufficient one; the real moat is a structured and verifiable trust data asset.

Start building enterprise core trust elements (qualifications, performance, credit, and compliance) into a machine-readable, certifiable, and queryable state with authorization.

rather than being locked in PPT and PDF files.

Prioritizing access to open, mutually recognized, and governance-neutral trust networks

stay away from the binding trap of "handing over the trust key to a single platform"

## Conclusion: Tickets are sold out, but most people haven't picked them up yet

In the era of intelligent systems, corporate competition appears to be about model capabilities, content, and traffic on the surface, but at its core, it is about "who can be trusted and verified by machines".

When your clients, partners, and even regulatory bodies start using AI entities to make automated decisions, the issue is no longer "how well your official website is written", but rather "whether your qualifications, performance, and credit have been structured, verified, and can be queried in real-time by third parties at the protocol level". A trusted data space is the foundation, third-party trusted data MCP is the interface, and trusted data infrastructure is the neural network - only when all three are in place can an enterprise truly obtain a ticket to enter the era of intelligent entities.

Companies still relying on content feeding logic to chase being "mentioned by AI" today should think one thing through: in the future, being trusted by AI is far more important than being recommended by AI. And trust has never been written, but verified.
